Proposed standards

The following standards are being proposed and drafted. You cannot view these standards at this time.

Standard Description
Application Programming Interface (API) Management Platform A standard service where the department can host, build and maintain APIs. All DfE APIs must be hosted on an approved API management platform. Providing a central hub for API lifecycle management will enable the department to monitor API traffic, enforce security policies and improve user experience
Content Management Systems (CMS) Content management systems provide teams with the ability to manage content in products and services through user-friendly editors without having to make changes through source code.
Data Access Control Data access control is a protective strategy that manages who can access, modify, or view specific data. It’s an integral part of cybersecurity and data management, maintaining the privacy, confidentiality, integrity, and availability of sensitive information through restrictions and permissions.
Data Decommissioning Data decommissioning is the process of retiring and removing data systems, applications, or services that are no longer needed. This involves ensuring that any data stored in these systems is either transferred to a new system, archived for future reference, or securely deleted if it’s no longer required.
Data Mapping In DfE data mapping captures all data, where and how it enters our estate, where it is stored, how it flows throughout the department and what purpose it is used for.
Decommissioning Standard
End User Computing Devices (laptops and phones) This standard defines client devices to be used within DfE. It applies to devices used by DfE staff, managed services and contingent workers to access corporate (as opposed to sector or public-facing) DfE services and data.
Licencing source code
Metadata Management Effective metadata management ensures consistent organisation, discovery, comprehension, and utilisation of DfE’s data throughout its lifecycle.
Storing source code
Technical Standard: Corporate Network Boundary Protection